Including the five attacks the comparison page attracts. They are answered here rather
than waiting to be asked, because an answer written under pressure is worth less than one
written in advance.
The category itself
What this is, what it is not, and the two attacks the comparison page attracts first.
Is this open source?
No. Purpose Source is not open source, and we say so proudly. The licence conditions
commercial use by organisations above a revenue-and-headcount threshold, which fails the
Open Source Definition, so the label does not apply and we never claim it.
What we do claim is narrower and checkable: public source, forks, modification,
redistribution, free use for individuals and organisations below the threshold, no
copyright assignment ever, and automatic conversion of every version to Apache-2.0 four
years after its release — written in the licence text, not promised in a blog post.
Open source needs no replacement. This is a complement, for products whose maintainers
deliberately choose it.
link to this answer
Your comparison table implies parity. It is not the same thing. rebuttal kit
Correct, and the first content row of the comparison page says so before any tick mark
appears. Comparison is not equivalence.
The table exists because the question maintainers actually ask is “what changes for my
community?”, and the honest answer has three parts: a long list of things that do not
change, a shorter list of things this adds, and a list of places where open source keeps a
real edge. That third part is not collapsed, not hidden behind a toggle, and not placed
below the fold — a build assertion fails the site if it ever is.
link to this answer
Every fee-for-commercial-use licence before this one died. Why would yours survive? rebuttal kit
It may not. The graveyard is our syllabus rather than our embarrassment: the post-mortem of
prior attempts publishes with honest odds, not as marketing.
What is different is narrow and structural, and each item is checkable:
- One canonical text, zero parameters. The legal review happens once per category, not
once per project. Every adopter ships the identical file.
- SPDX identifier requested at launch, so scanners can name the thing rather than
flagging it as unknown.
- Machine-readable entitlements. A procurement team gets a signed record and a
verification page, not an email thread.
- An escrow launch, so no first adopter stands alone: the licence goes live only when a
published minimum of projects and payers is in place.
- Counsel memos in three jurisdictions before launch, published.
- The adopter’s worst case is capped in the text. Versions vest permanently, the
four-year Apache-2.0 conversion is unconditional, and a steward-lapse backstop turns the
licence permissive if this organisation stops operating.
We can fail. Adopters cannot be stranded. Those are two different risks, and only the first
one is ours to take.
link to this answer
What if the Association fails?
Then the licence takes care of itself, because the guarantee is written into the text rather
than into a promise from us.
- The steward-lapse backstop. If the Steward Organization ceases to exist, or stops
issuing Entitlements for twelve consecutive months with no publicly designated successor,
the Purpose Condition lapses and the licence degrades to permissive terms.
- Vesting is unaffected. Every version a payer vested stays usable, permanently.
- The conversion keeps running. Each version becomes Apache-2.0 on the fourth anniversary
of its release whether or not anyone is here to administer it.
The wind-down itself is a standing, pre-published page — the kill protocol:
pre-registered criteria for stopping, the registry archived at permanent URLs so no badge and
no verification link dies, the key set retired but still valid so issued certificates keep
verifying, remaining funds disbursed to the category funds, and a post-mortem published.
We can fail. Adopters and payers cannot be stranded. Those are two different risks, and only
the first is ours.
link to this answer
Can I fork a Purpose Source project?
Yes. Fork, clone, modify, redistribute — the licence keeps all of it. What a fork carries with
it is the same licence and the same condition: an organisation above the threshold using your
fork’s new releases needs an Entitlement exactly as it would for the original.
Two more things worth knowing:
- The last permissive version is forkable too. When a project converts from MIT or
Apache-2.0, everything already published stays under that licence forever, and anyone may
fork it from there. That is the fork risk a maintainer accepts on adoption; the
administrator page states it plainly rather than hiding it.
- Old versions are Apache-2.0. Any version four years old or older is on ordinary
permissive terms, fork included.
How waivers and Entitlements follow a fork — a waiver is designed to travel with the work it
covered when granted, an Entitlement with the registry record — and which fork counts as the
canonical repository, are clauses being drafted with counsel. They will be stated in the
licence text and its plain-English companion, not decided case by case.
link to this answer
What is a sandbox or test certificate, and why does this preview say "sample data"?
Two different honesty markers, one rule behind both: nothing on this site is presented as
real before it is.
Sandbox certificates are signed with a sandbox key rather than a production key. The
verification page recognises the key and renders such a certificate under a red
“test certificate” banner — never as a production credential, however valid the signature.
Integrators use them to test a policy engine or a procurement workflow end to end without a
real Entitlement existing.
Sample data is what this preview deployment shows in its registry, its ledger and its
certificates: labelled rows that describe no real repository, no real payment and no real
disbursement. Each such surface carries a “Sample data” ribbon, and a production build refuses
sample data outright at build time, so the two can never be confused on the production host.
One rule ties them together: certificates are verified at purposesource.org/verify and nowhere
else. A certificate that verifies anywhere else is not one of ours.
link to this answer
For repository administrators
Adopting, leaving, waivers, and whether your repository is the right shape for it.
Some employers bar contributions to licences like this, and Linux distributions will never ship it. rebuttal kit
Both true. Both priced in. Both stated here rather than discovered later.
Some open source programme offices bar contribution to any licence that is not
OSI-approved, exactly as they do for every BUSL or FSL project. That is a real cost to a
project that adopts this licence, and we will not claim it is zero — a single screenshot
of an internal policy would refute us.
Two things soften it. The four-year Apache-2.0 conversion means even the strictest shop can
consume, pin, and eventually contribute to older versions on ordinary permissive terms. And
the licence follows function: this text is meant for deliberately-adopted products, not for
libraries deep in a dependency tree, and our own ecosystem repositories stay MIT or Apache.
We would rather lose contributors honestly than win them by pretending the cost does not
exist.
link to this answer
How do I adopt, and how do I leave?
Adoption is one committed file: the canonical LICENSE text, complete on merge. No account,
no registration, no handover, no copyright assignment. A manifest file for per-project
overrides exists and is entirely optional — defaults apply when it is absent, and that is
the normal case.
Leaving is the same act in reverse: change the licence file back. The repository is the
source of truth and the registry follows it. There is no notification duty, no exit
interview, and no penalty.
Two consequences to know before either step:
- Past releases keep the licence they shipped under, forever. Adoption aims the future;
it cannot reach back into releases already published under another licence.
- Payers keep what they paid for. Every version whose publication date falls on or
before the end of a payer’s term stays usable by them permanently, whatever the repository
does afterwards.
Verified listing, the badge, and waiver powers need a lightweight claim — proving repository
administrative control — but the licence works fully without it.
The full walkthrough, including the inbound-licence check to run before adopting, is in the
adoption guide.
link to this answer
Is this licence for libraries?
No, and we would rather tell you than let you find out. The design target is a product an
organisation deliberately adopts — something a team chose, installed and runs. A dependency
deep in a tree, pulled in by a package manager and read only by a scanner, is the wrong shape
for a licence whose compliance path is a conscious purchase.
Two consequences follow and both are stated openly. Package registries and Linux distributions
will not ship a library under this licence, and that is a library concern this licence does
not try to solve — versions four years old and older qualify normally as Apache-2.0. And our
own ecosystem repositories stay MIT or Apache-2.0: licence follows function, including for us.
If your repository is a library, this is the wrong licence for it. If it is a product with
libraries inside it, adopt for the product and leave the libraries on their own terms.
link to this answer
Can a maintainer exempt a company from the fee?
Yes — that is the waiver, and it is the administrator’s power, not ours. The licence vests
in the Project Steward (the administrator of the canonical repository) the power to excuse a
named organisation from the Purpose Condition for that repository. The Association records
and witnesses it; the administrator grants it.
The rules are fixed and public:
- Public, always. Every waiver appears in the waiver registry. A private
exemption would make coverage unanswerable, and is the side-deal this structure exists to
prevent.
- Gratis, always. Selling one is a delisting offence. A waived organisation receives a
licence-status certificate only — never a supporter or impact certificate, because it funded
nothing.
- Repository-scoped, grantable and revocable by any verified administrator, with every
co-administrator notified and one shared audit log.
- Revocation is prospective, with versions vested by the same formula that protects payers.
- A 72-hour cooling window. The organisation is covered immediately, but permanent vesting
attaches only when the window closes; a revocation inside it voids the waiver from the
start. Grants require a step-up re-authentication, so a compromised account cannot mint
permanent rights in the minutes before anyone notices.
- Unclaimed repositories have no waivers. Waiving requires the two-minute claim.
The full description is on the administrator page.
link to this answer
For contributors
What a merged contribution earns, and the two things it deliberately never earns.
Do contributors get paid?
No. Contributors direct money; they never receive it. That distinction is structural,
not stylistic: a mechanism that paid contributors from licence fees would turn every merge
decision into a payment decision, and would make the steward a payroll rather than a
registry.
What a merged contribution earns is an attributed Impact Share under a published algorithm,
a vote on which vetted cause areas the project’s flow supports, and a signed, verifiable
certificate of participation. Attribution display is gated by materiality, and there are no
leaderboards.
The design intent is that this is the most meaningful line a contribution can add to a
professional record. Whether it works is a question for testimonials after launch, not a
claim for today.
link to this answer
Why are there no leaderboards?
Because a leaderboard would rank people by a number an algorithm attributes to them, reward
optimising for that number, and expose contributors whose employers would rather they were not
listed at all. None of those is recognition; all three are the failure mode of it.
Recognition here is coarse on purpose. Points and percentiles are always shown; a per-person
currency figure appears only above a published materiality floor, because below it the
number is real but too small to mean what a reader would take it to mean — precision-shaming,
not transparency. There are percentiles, not ranks; profiles are claimed, not scraped; a
certificate is something you choose to show, not a table someone else compiles about you.
Aggregates are different. A project’s lifetime public-benefit figure and the network’s ledger
total publish in full, because they are ledger facts about money, not judgements about people.
The impact page shows where the gate falls, with sample figures labelled as such.
link to this answer
For companies and their compliance teams
The threshold, the cure window, vesting, scanners, and the donate-direct lane.
For a large company the annual fee is a rounding error. Is this not just virtue-badge vending? rebuttal kit
The paperwork forbids it, which is the only answer worth giving.
The base credential is marketed as compliance, not generosity — the product is one flat
annual licence, one review, machine-verifiable proof. Certificates ship with a
claim-language kit that states the exact wording a buyer may use; generic
“we support charity” framing is contractually excluded. Organisations holding a gratis
waiver receive status certificates only, with no funding claim available to them at all.
Prominence is earned by real multipliers, not by the base fee: the voluntary
impact-multiplier tiers exist precisely so that a company wanting a creditable story has to
pay for one. We also never frame the fee as beneath a large organisation’s attention —
scanners read a licence at zero cost, and a stealth framing would be both untrue and
insulting.
Tiny cost per payer, distributed impact, and no permission to exaggerate either. That is the
whole design.
link to this answer
Who has to pay? The threshold, in plain English
Two tests, and an organisation is free only while both are true, measured across its
whole group in its own prior tax year:
- fewer than 100 people — employees and independent contractors counted together; and
- less than one million US dollars in total revenue, in 2026 terms — the figure is
indexed to US consumer prices each year and converted at the tax year’s average official
exchange rate, so it does not silently tighten with inflation or drift with currencies.
Below both: nothing to pay, nothing to register, nothing to sign — the licence behaves
permissively. Above either: new releases need a current Entitlement, a waiver granted by the
project, or a recorded direct donation, with a 60-day cure window before anything is
out of licence.
The test is self-assessed against your own figures. There is no audit right anywhere in
the licence or the Entitlement terms. The licence itself is binary — small, or not; the
revenue bands and their prices live in the published fee schedule, never in the
licence text. Where this paragraph and the licence text differ, the text wins.
link to this answer
What does "group" mean in the threshold?
Your organisation plus every organisation under common control with it — direct or
indirect, through ownership, voting power, contract, or otherwise. The wording is the control
language of the PolyForm Small Business licence, used verbatim rather than paraphrased, because
that text has already been read by the programme offices that will read this one.
The consequence is the point: a small subsidiary of a large parent is inside the parent’s
group, and a holding structure cannot split itself below the threshold. Both the headcount
test and the revenue test are measured over the group as a whole.
Why it is drawn this way: a revenue-only test lets a well-funded, pre-revenue company with a
thousand engineers ride free, and an entity-only test lets the largest organisations ride free
through structure. Either would be the opposite of the design.
link to this answer
What is the 60-day cure window?
Crossing the threshold is not a violation on day one. From the day your organisation first
fails the condition — because it grew past the threshold, or because an Entitlement lapsed —
your permissions continue for 60 days. Buy an Entitlement, obtain a waiver from the
project, or record a direct donation inside that window, and nothing was ever out of licence.
So growth never creates an overnight infringer, and a late renewal is a task for the person
who handles renewals, not a compliance incident. A lapsed Entitlement additionally answers
coverage queries as “lapsed, in grace” rather than “no” during a published grace period, so a
scanner sees the same thing your team does.
The cure window is also how amnesty covenants on purchase fit together with everyday
compliance. Purchase triggers covenants not to sue for past use from the Steward Organization
and from the project’s steward-of-record, to the extent grantable; the cure window covers the
rest. Friendly compliance, never ambush.
link to this answer
If we stop paying, what happens to the versions we already use?
You keep them, permanently. The formula has one sentence: a version is vested to you if and
only if its publication date falls on or before the end of your paid term.
Every Entitlement is annual. At activation you vest the whole back catalogue plus every
version published during the term; each renewal extends the term end into the next year’s
releases. The rule is uniform across the Project, Portfolio and Pass lanes, and across waivers
too — for a waiver, “term end” is the moment of revocation or expiry.
Nothing strips a vested version: not the project leaving the licence, not delisting, not the
steward failing, not a waiver being revoked, not your own decision to stop renewing. If you
stop, you keep everything you vested and simply stop accruing new releases. This is the
answer to a vendor-risk review, and the reason a credential from an organisation you have
never heard of can be trusted at all.
link to this answer
Will my licence scanner recognise it?
Not yet, and probably not for a while. No SPDX identifier has been requested for the licence
at this stage; the request is planned, with the founding cohort’s adoption as the evidence the
listing process asks for. Until an identifier is listed and the scanner vendors carry it,
expect “unknown licence” flags from compliance tooling on any repository that adopts.
We state the lag honestly because it is the window in which fee-based licences have quietly
died before. The bridge is built from things that exist independently of a listing: one
canonical, zero-parameter text that a policy engine can match byte for byte; a signed,
machine-readable Entitlement record and a public verification page; a review pack written for
the person who has to approve or deny; and proactive submissions to the scanner databases as
adoption evidence accrues.
Where the request stands is printed on the licence page as a status field, and
that field is allowed to say “not requested yet”.
link to this answer
Can we donate directly instead of paying a fee?
Yes. The Donation Entitlement is a compliance lane, not a priced product. An organisation
makes a documented direct donation of the applicable tier amount to a listed partner fund; the
donation is recorded in the same registry as every other Entitlement; and the registry answers
“yes, via Donation” to the same coverage question everyone else asks.
The money never touches the Association. That is the lane’s purpose: it exists for
organisations whose policy forbids paying a licence fee but permits a charitable payment, and
it preserves a payer’s choice about the character of the payment rather than forcing one.
The proof standard for the donation, the recording mechanics, and the payer-side character of
the payment are being drafted with counsel and will be published in the Entitlement terms.
Until then the lane is described here as designed, not as open.
link to this answer
The money
The pledge and its qualifiers, who audits it, and how the fee is treated for tax.
Who audits you? How would anyone know the money actually reaches charity? rebuttal kit
The pledge has one wording and it is deliberately qualified: 100% of net proceeds after
published, capped operating costs (cap: set with counsel before launch, audited). We never
state it in an unqualified form, in any channel, because the unqualified form is false the
moment a payment processor takes its cut.
Four mechanisms, none of which requires trusting us:
- The full fee stack is published as one figure — merchant-of-record fee, intermediary
fee, capped operating levy, currency drag — before any journalist computes it for us.
- The allocation ledger is append-only. Corrections are new rows; annotations render as
annotations. Monthly exports are immutable once written and carry a hash chain.
- Accounts are audited and the audit reports publish on the Trust Center as they exist.
- Neither the steward nor any repository owner can be a recipient. That is a structural
bar in the statutes, not a policy we could quietly revise.
What we do not claim: that every step of the banking and intermediary leg is publicly
provable end to end. It is not, and saying otherwise would be the easiest overclaim to
puncture. The claim we do make is that every recorded allocation and disbursement is
independently reconcilable — append-only ledger, audited accounts, partner receipts.
Until money has moved, there is nothing to audit and this site says exactly that.
link to this answer
Is the Purpose Fee tax-deductible?
We can only answer this carefully, so here is the careful answer. The Purpose Fee is
structured and invoiced as a software-licensing business fee; tax treatment depends on the
payer’s jurisdiction and circumstances — purchasers should obtain their own advice.
The comparative point survives only in qualified form: a licence fee is typically
better-treated than a cross-border donation, which is capped or non-deductible in many
jurisdictions. That is a comparison, never a guarantee, and nothing on this site promises a
particular return to a particular payer. The donate-direct lane exists so
that an organisation which prefers a charitable payment keeps that choice.
Two related facts about the Association itself. Its own public-benefit tax exemption has been
applied for in the canton of Aargau and is pursued, never assumed — no page describes it
as tax-exempt before the ruling exists. And Entitlements are supplies of services for Swiss
VAT purposes: foreign customers are generally outside Swiss VAT under the recipient-location
rule, Swiss customers pay the Swiss rate, and where a merchant of record sits in the stack it
handles indirect tax on cross-border sales.
link to this answer